Now these do use advanced AI algorithms, Bayesian, ... etc. But it's one factor out of hundreds, and they are nowhere near the top.
Now at Google and Facebook, the rules are like the rules of a firewall. Some new type of spam comes out, it gets past the filters, they look at it, they write a new rule. After 10 years of this with 50 people doing that fulltime you have thousands of rules and it doesn't look like a set of rules anymore. This is why those companies don't get blown out of the water every time a PhD realizes how to make the basic algorithm perform 5% better.
They don't really use the newest algorithms at all. With gmail it's obvious since some of the tricks it knows are things a machine learning algorithm could never ever figure out, for instance how to look up flight times, or package status. No amount of training on mails will ever yield that. Furthermore, they have custom "cards" and other small custom UIs that get triggered by their "AI" classification.
Of the remaining 5%, 4.95% is still the same principle, but basic algorithms can adapt it a bit : human designed rules, but a linear or logistic regression over the data of the past 5 (minutes, hours, days, weeks, months) can make the rule 10% stricter or looser.
The only real "advanced" AI is speech-to-text and in Google's case image search.